CWE-129
High likelihoodImproper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
572 vulnerabilities with CWE-129
CVE-2022-42255
MEDIUM
NVIDIA Virtual GPU < 11.11 and Cloud Gaming < 525.60.11 - Out-of-Bounds Array Access in Kernel Mode Layer
CVSS 5.3
CVE-2022-42254
MEDIUM
NVIDIA GPU Display Driver 470-470.161.03 - Out-of-bounds Read in Kernel Mode Layer
CVSS 5.3
CVE-2022-31745
MEDIUM
Firefox < 101.0 - Use-After-Free via Garbage Collector Array Shift Confusion
CVSS 4.3
CVE-2022-2951
HIGH
Altair HyperView Player < 2021.1.0.27 - Memory Corruption via H3D File Processing
CVSS 7.8
CVE-2022-25711
MEDIUM
Qualcomm Firmware - Memory Corruption in Camera via Array Index Validation Issue
CVSS 6.7
CVE-2022-25695
HIGH
Qualcomm APQ8009 Firmware - Memory Corruption via GSTK Proactive Command Processing
CVSS 8.4
CVE-2022-46152
HIGH
OP-TEE Trusted OS <3.19.0 - Buffer Overflow
CVSS 8.2
CVE-2022-25720
CRITICAL
Qualcomm APQ8009 and related firmware - Memory Corruption via WLAN Out-of-Bounds Array Access
CVSS 9.8
CVE-2022-42011
MEDIUM
Freedesktop Dbus < 1.12.24 - Improper Array Index Validation
CVSS 6.5
CVE-2022-25690
HIGH
Qualcomm Firmware - Information Disclosure via ANQP Action Frame Array Index Validation
CVSS 7.5
CVE-2022-22099
HIGH
Snapdragon Auto - Memory Corruption
CVSS 8.4
CVE-2022-35737
HIGH
SQLite 1.0.12-3.39.x - Array Index Overflow via String Argument to C API
CVSS 7.5
CVE-2022-31135
MEDIUM
Akashi < 1.4 - Denial of Service via Crafted Evidence Packet
CVSS 6.5
CVE-2022-31603
MEDIUM
NVIDIA DGX A100 Firmware < 22.5.5 - Authenticated Code Execution via IpSecDxe Array Index
CVSS 6.4
CVE-2022-30763
HIGH
janet < 1.22.0 - Improper Validation of Array Index
CVSS 7.5
CVE-2022-1237
HIGH
radare2 < 5.6.8 - Heap Overflow via Improper Array Index Validation
CVSS 7.8
CVE-2022-27223
HIGH
Linux Kernel < 5.16.12 - Out-of-Bounds Write via USB Gadget Endpoint Index
CVSS 8.8
CVE-2022-26100
CRITICAL
SAPCAR 7.22 - Denial of Service and Privilege Escalation via Archive Input Validation
CVSS 9.8
CVE-2022-21310
MEDIUM
Oracle MySQL Cluster <= 7.4.34, <= 7.5.24, <= 7.6.20, <= 8.0.27 - Authenticated Remote Code Execution
CVSS 6.3
CVE-2021-4439
HIGH
Linux Kernel < 4.4.290 - Array Index Out-of-Bounds in ISDN CAPI Controller Detachment
CVSS 7.8
CVE-2021-47548
CRITICAL
Linux Kernel < 4.9.292 - Array Index Validation Bypass in hns_dsaf_ge_srst_by_port
CVSS 9.8
CVE-2021-47547
MEDIUM
Linux Kernel < 4.4.294 - Out-of-Bounds Array Access in Tulip DE4X5 PHY ID Handling
CVSS 4.4
CVE-2021-47449
HIGH
Linux Kernel 5.14.4-5.14.14 - Deadlock via Tx Timestamp Tracking Flush
CVSS 7.1
CVE-2021-47135
HIGH
Linux Kernel 5.12-5.12.9 - Array Index Out-of-Bounds Access in mt7921_mcu_tx_rate_report
CVSS 7.8
CVE-2021-47065
HIGH
Linux Kernel rtw88 - Array Index Out-of-Bounds in rtw_get_tx_power_params
CVSS 7.8
Details
Vulnerabilities
572
Exploit Likelihood
High